Privacy Policy
Data controller: Datim-QI Ltd · Version 2.0 · Last updated: 30 July 2026
1. Introduction
This Privacy Policy explains how Datim-QI Ltd(“we”, “us”) collects, uses and protects personal data when you use Datim-QI. Datim-QI helps NHS general practice teams benchmark and improve their QOF, prescribing and clinical-audit position using published, aggregate NHS data. It is not designed to, and must not be used to, process patient-identifiable data.
2. What we collect
Account data, provided by you when you register or use your account:
- Email address and password (password is handled by our authentication provider, Supabase — we never see it in plain text)
- Full name and professional role (e.g. GP, practice manager)
- Your practice’s NHS ODS code and name, and its PCN/ICB affiliation (public NHS organisation identifiers, not personal to any patient)
Data generated by using the service:
- Saved AI-generated quality-improvement plans and their generation history, linked to your practice
- Your viewing/session preferences (e.g. which practice you are currently viewing)
Technical data, collected automatically:
- IP address, browser type and device information
- Authentication session cookies (see the Cookie Policy)
We do not collect and the service must never be used to submit patient names, NHS numbers, dates of birth, or any other patient-identifiable or special-category data.
3. How we use your data
- To create and operate your account and show you the correct practice’s benchmarks
- To generate AI quality-improvement plans and prescribing/clinical-excellence suggestions at your request
- To maintain the security, reliability and performance of the service
- To respond to support or data-rights requests you send us
We do not use your data for marketing, advertising, profiling, or any automated decision-making that produces legal or similarly significant effects on you.
4. Legal basis for processing
We process account and usage data under Article 6(1)(b) UK GDPR (performance of a contract) — it is necessary to provide the account and features you sign up for. Where we ask for consent (for example, for any future non-essential cookies), the basis is Article 6(1)(a) (consent), which you can withdraw at any time.
5. AI processing
When you request an AI quality-improvement plan, we send your practice’s aggregate benchmark position (QOF indicator rates, register and list sizes, prescribing deciles, clinical-audit rates, and your practice name and ODS code — never any individual patient data, and no personal data about you) to a third-party AI model provider to generate the draft plan text.
We use a single provider, Anthropic, for every AI feature — the whole-practice plan and the smaller per-indicator and per-step plans alike. It processes the data under its own commercial API terms. Its processing location is set out in §7.
The generated plan is saved to your account so you can view it again later. We may change which AI provider we use from time to time; we will update this policy, and the same data-minimisation rule (aggregate practice-level data only, never individual patient data) always applies.
6. Who we share data with
We use the following processors to operate Datim-QI:
- Supabase — database hosting, authentication and account storage. Processes your account data. Region: [TO CONFIRM — UK/EU].
- Cloudflare — application hosting. Processes request logs; stores no account data. Region: [TO CONFIRM — UK/EU].
- Anthropic (United States) — generates all AI quality-improvement plan text. Receives aggregate benchmark figures only (see §5).
- Our transactional email provider — sends account and sign-in emails. Processes your name and email address.
We do not sell your data or share it with anyone for marketing purposes. We may disclose data where required by law or to a regulator.
7. International transfers
Two different kinds of data leave our systems, and different rules apply to each. We describe both so you can see exactly what goes where.
(a) Your personal data. The only personal data we hold is your account data (§2). Our database, authentication and hosting providers are configured to process it in the UK or European Economic Area [TO CONFIRM]. Where any personal data is transferred outside the UK, we rely on the UK International Data Transfer Addendum, standard contractual clauses, or another safeguard recognised under UK GDPR. No personal data is sent to the AI provider.
(b) Aggregate benchmark data, which is not personal data. The figures we send to our AI provider are published, practice-level NHS statistics — indicator rates, register and list sizes, prescribing deciles, audit rates — together with your practice name and NHS ODS code. This contains no personal data and no patient data of any kind. The UK GDPR restrictions on international transfers apply to personal data, and so do not apply to this flow. We tell you where it goes anyway, because you are entitled to know: Anthropic processes it in the United States. All of this data is already published openly by NHS England, the Bennett Institute, CVDPREVENT and the National Diabetes Audit, and can be downloaded by anyone.
If your organisation’s policy is that no data of yours should be processed in a particular country, tell us.
8. Data retention
We keep your account and saved plan data for as long as your account is active. If you want your account and associated data deleted, email gp.drgillespie@gmail.com and we will action this within 30 days (self-service account deletion is not yet built into the product). Technical logs are retained only as long as needed for security and troubleshooting.
9. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure of your data (“right to be forgotten”)
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent, where processing is based on consent
To exercise any of these rights, email gp.drgillespie@gmail.com. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
Datim-QI Ltd is registered with the ICO as a data controller (registration reference to follow).
10. How we protect your data
- HTTPS encryption in transit
- Authentication and access control via Supabase, with row-level security scoping data access to your own practice
- Passwords are never stored or visible to us in plain text
- Access to production data is limited to what is needed to operate the service
11. Children’s data
Datim-QI is a professional tool for NHS practice staff aged 18 and over. We do not knowingly collect data from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always available on this page. Continued use of Datim-QI after an update means you accept the changes.
13. Contact
Datim-QI Ltd
Email: gp.drgillespie@gmail.com
Datim-QI Ltd is a company registered in England and Wales, company number 17370894. Registered office: 82a James Carter Road, Mildenhall, IP28 7DE, United Kingdom.